2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-21197MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t...
CVE-2024-21196MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are af...
CVE-2024-21195HIGH7.6Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions ...
CVE-2024-21194MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2024-21193MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected...
CVE-2024-21192MEDIUM4.4Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Fusion Middleware (component: Web...
CVE-2024-21191HIGH7.6Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Middleware (component:...
CVE-2024-21190HIGH7.5Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cl...
CVE-2024-21172CRITICAL9Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). ...
CVE-2024-41344HIGH7.5A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator passw...
CVE-2024-35584HIGH8.8SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingL...
CVE-2024-5749HIGH7.5Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.
CVE-2024-48915HIGH8.7Agent Dart is an agent library built for Internet Computer for Dart and Flutter apps. Prior to version 1.0.0-dev.29, cer...
CVE-2024-9676MEDIUM6.5A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage lib...
CVE-2024-9506LOW3.7Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulner...
CVE-2024-48914CRITICAL9.1Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's as...
CVE-2024-48913MEDIUM5.9Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by...
CVE-2024-48624MEDIUM5.3In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a refl...
CVE-2024-48623MEDIUM5.3In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited ...
CVE-2024-48622MEDIUM6.6A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admi...
CVE-2024-47876HIGH8.8Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users crea...
CVE-2024-47874HIGH8.7Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treat...
CVE-2024-47824HIGH8.7matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starti...
CVE-2024-47779HIGH7Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a ...
CVE-2024-47771HIGH7Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vul...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now